Impact
An off‑by‑one error in the forcedeth driver causes the nv_suspend() and nv_resume() routines to read from and write to one element past the end of a statically allocated array while copying non‑PCI configuration space. The out‑of‑bounds access triggers a UBSAN trap that aborts the kernel when UBSAN is enabled, or silently performs an illegal MMIO read or write when UBSAN is disabled, resulting in a kernel crash that brings the affected system down and yields a denial‑of‑service condition.
Affected Systems
All Linux kernels that include the forcedeth driver without the loop‑bound fix commit (changing '<=' to '<') and that support suspend or resume distribution forcedeth module are vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity, while the EPSS score is below 1 %, implying a very low probability of exploitation. The vulnerability is not listed in CISA KEV. It is inferred that an attacker would need local system access or the ability to trigger suspend/resume cycles for a device managed by forcedeth—e.g., by sending a power‑management event or manipulating the power state. Because the fault leads to a kernel abort when UBSAN is enabled, the impact is largely limited to system availability rather than confidentiality or integrity. The overall risk remains high due to the severity of the crash exploitation.
OpenCVE Enrichment
Debian DSA